Malvertising now hides attacks behind fake ads

Published August 20, 2026

Ads that look completely normal can secretly send you somewhere dangerous after you click, sometimes only if you match the attacker's target profile. Fraud networks now hide the malicious step deep in a chain of redirects instead of putting it in the ad itself.

Report priority
Medium
Targets
PropellerAds

How it works

An ad passes moderation with a clean creative and landing page, then routes clicks through tracking links and disposable domains that check your location, device, and browsing behavior before deciding what to show you, so investigators checking the ad later see something harmless while real targets get redirected to a fake site.

What to do

This is an ad-delivery tactic, not a bug in a specific product, so most readers are not individually named but anyone who clicks an ad and lands on a login page for a trading or crypto brand should pause and check the web address before entering credentials.

Do not enter passwords, seed phrases, or account details on a page you reached by clicking an ad. Type the real site's address directly into your browser or use its official app, and report suspicious ads to the platform where you saw them.

Technical details

Affected software: PropellerAds

A malicious ad campaign runs since late 2024, impersonating brands including TradingView, Solana, and Luno across 12 countries and 25 languages. Its landing pages fingerprint each visitor: suspected researchers and bots get an empty, harmless page, while people who match the target profile get a convincing fake copy of the real service's site. Because the fake page only appears to real targets, anyone reviewing the ad after the fact can miss the scam entirely.

Ad-network moderation data from PropellerAds shows malware and antivirus-flagged rejections rose from 8,408 in Q1 2026 to 9,543 in Q2, growing from 23.3% to 45.9% of all rejections even as total rejections fell 42%. Cloaking, where a campaign hides its real destination or behavior from reviewers, stayed the top suspension cause at 67.3% of advertiser suspensions. GeoEdge separately found redirect-based attacks rising from 48% to 66% of malicious ad activity in 2025, and Google's H1 2026 telemetry attributed almost 30% of its threat detections to malvertising. A documented Confiant campaign active since late 2024 impersonated TradingView, Solana, and Luno across 12 countries, fingerprinting visitors to serve fake login pages only to real targets.